US11677552B2

Method for preventing misuse of a cryptographic key

Summary by NHIP

Quorum-based key authorization method

The method prevents cryptographic key misuse by distributing requests to a quorum of devices that decide based on policies selected by device types. The policy updates based on request complexity levels derived from the sensitivity of data accessed after the operation.

Claim Score by NHIP

Read claim 1, the broadest

Abstract

Preventing misuse of a cryptographic key by receiving a request to carry out a cryptographic operation using a cryptographic key from a requesting entity, distributing the request to a quorum comprising multiple computerized devices, receiving a decision from the multiple computerized devices on whether or not the cryptographic operation using the cryptographic key is allowed, and carrying out the cryptographic operation using the cryptographic key according to the decision from the multiple computerized devices.

US11677552B2, drawing sheet 1
Sheet 1 of 5

Term

15 yearsleft in the term

Expires 9 September 2041.

  1. Priority and filed
  2. Granted
  3. Today
  4. Expires

18 claims: 2 independent, 16 dependent

  1. 1
    Broadest claimClaim Score 49, average(NHIP)A method for preventing misuse of a cryptographic key utilizing quorum authorization in a policy engine for fraud detection, wherein the policy engine comprises a set of rules that governs if fraud detection operations may occur, the method comprising:receiving a request, from a requesting entity, to carry out a cryptographic operation using a cryptographic key;distributing, by the policy engine, the request, over a communication network, to a quorum comprising multiple computerized devices, wherein the computerized devices in the quorum determine whether or not to allow the cryptographic operation using the cryptographic key based on a policy, wherein the policy is selected based on device types of the multiple computerized devices, and wherein the policy is updated by: evaluating a complexity level of the request;andupdating the policy in at least some of the computerized devices in the quorum based on the complexity level of the request, wherein the complexity level of the request is based on a sensitivity of data to be accessed after carrying out the cryptographic operation;receiving a decision from the multiple computerized devices on whether or not the cryptographic operation using the cryptographic key is allowed;andcarrying out the cryptographic operation using the cryptographic key according to the decision from the multiple computerized devices.
  2. 13
    A system for preventing misuse of a cryptographic key utilizing quorum authorization in a policy engine for fraud detection, wherein the policy engine comprises a set of rules that governs if fraud detection operations may occur, the system comprising:one or more processors;andnon-transitory computer readable medium comprising instructions that when executed by the one or more processors cause operations comprising:receiving a request, from a requesting entity, to carry out a cryptographic operation using a cryptographic key;distributing, by the policy engine, the request, over a communication network, to a quorum comprising multiple computerized devices, wherein the computerized devices in the quorum determine whether or not to allow the cryptographic operation using the cryptographic key based on a policy, wherein the policy is selected based on device types of the multiple computerized devices, and wherein the policy is updated by: evaluating a complexity level of the request;andupdating the policy in at least some of the computerized devices in the quorum based on the complexity level of the request, wherein the complexity level of the request is based on a sensitivity of data to be accessed after carrying out the cryptographic operation;receiving a decision from the multiple computerized devices on whether or not the cryptographic operation using the cryptographic key is allowed;andcarrying out the cryptographic operation using the cryptographic key according to the decision from the multiple computerized devices.